Static Web Apps: custom domain add fails with "unknown error", the entry sticks in Deleting, and the app itself can no longer be deleted

Dmitry Mizernik 0 Баллы репутации
2026-08-13T14:49:47.4533333+00:00

Body

Adding a custom domain to a Static Web App fails after ownership validation succeeds. The failed entry then cannot be deleted, and the Static Web App holding it cannot be deleted either. I reproduced the whole sequence on a brand-new app, so it does not look app-specific.

Environment

Region West Europe
SKU Free
Apps lprd-shell-dev (original), lprd-shell-dev-probe (created today to reproduce)
Resource group rg-lprd-frontend-dev
Domain dev.lprdai.com (subdomain, not apex), DNS hosted on Cloudflare

Subscription and resource IDs available on request.

What happens

  1. az staticwebapp hostname set --validation-method cname-delegation is accepted.
  2. Validate Static Site Custom Domain → Succeeded in the activity log.
  3. Create Static Site Custom Domain → Accepted, then Failed minutes later with ResourceOperationFailure: The resource operation completed with terminal provisioning state 'Failed'.
  4. The entry's errorMessage reads: "An unknown error has occurred while adding your custom domain. Please try again later."
  5. Every subsequent delete of that entry is accepted and never completes — status stays Deleting indefinitely (over 15 hours so far on the first one).
  6. Deleting the Static Web App itself now fails the same way: two attempts, each running ~10 minutes and ending in ResourceOperationFailure.

Interesting detail: the first attempt did issue a certificate — the stuck entry carries expiresOn: 2027-02-12 — so the failure appears to be after validation and certificate issuance, in the binding step.

Another detail that may help narrow it down: deleting a custom-domain entry works normally while it is still in Validating (it disappeared instantly when I tried). It only becomes undeletable once the add has failed.

Client-side configuration, already verified

  • dev.lprdai.com is a CNAME to the app's *.azurestaticapps.net default hostname, TTL 300, resolving correctly from public resolvers.
  • Cloudflare proxy is off (DNS only), so the CNAME resolves straight to Azure.
  • There are no CAA records on the zone, so certificate issuance is not blocked by CAA policy.
  • The apps themselves are healthy — both default hostnames return HTTP 200.
  • Free SKU allows two custom domains; only these entries exist, and all are subdomains (no apex).
  • Azure's own validation step succeeded, so DNS is visible to the service.

Reproduction on a new app

To rule out a problem with the original app, I created a second Static Web App in the same region and resource group, pointed the CNAME at it, and bound the same hostname. Result: identical — validation succeeded, create failed with the same message, and the entry is now stuck in Deleting there too.

Impact

  • The custom domain cannot be used; the app returns HTTP 404 for that hostname because it is not registered.
  • The original app is now undeletable, so its name cannot be reused and it will sit in the resource group indefinitely.
  • Infrastructure-as-code cannot reconcile the resource group while an undeletable resource remains.
Azure
Azure

Платформа и инфраструктура облачных вычислений для создания и развертывания приложений и служб, а также для и управления ими через глобальную сеть центров обработки данных, управляемых корпорацией Майкрософт.

Комментариев: 0 Без комментариев

Ваш ответ

Автор вопроса может устанавливать для ответов пометку "Принято", а модераторы — пометку "Рекомендуется". Благодаря этому пользователям становится проще понять, какой из ответов помог решить проблему автора.